Network attack event traceability processing method and device based on chaotic watermark, and medium
By collecting sensor data in the Industrial Internet of Things (IIoT), calculating uncertainty indicators, and embedding chaotic watermarks, the real-time and path correlation problems of network attack tracing in the IIoT are solved, enabling real-time response and location of attack behaviors.
Patent Information
- Application Number
- CN202511333062.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-09-18
AI Technical Summary
Existing network attack attribution technologies lack real-time response capabilities in industrial IoT environments and lack the ability to model the correlation of physical layer attack propagation paths.
By collecting real-time data from industrial IoT sensors, calculating uncertainty indicators of device behavior, generating attack judgment flags and abnormal propagation paths, embedding chaotic encrypted watermarks in control commands, monitoring the deviation between execution results and expected physical behavior, and generating attack source coordinate information and attack path maps.
It enables real-time response to attacks in the Industrial Internet of Things (IIoT), ensures the physical executability of control commands, and can locate tampered bits, thus solving the problems of insufficient real-time performance and missing physical layer path association in existing technologies.
Smart Images

Figure CN120811802B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of industrial internet of things security technology, and in particular to a network attack event traceability processing method based on chaotic watermark, a device and a medium. BACKGROUND
[0002] Network attack traceability technology is a core research direction in the field of network security, and in recent years has made progress in theory and practice. Existing traceability methods mainly rely on network traffic analysis, log record analysis and malicious code reverse engineering, etc. Attack features or behavior patterns are extracted to realize attack source positioning. For example, IP address-based traceability technology traces the geographical location of the attacker through WHOIS query and Traceroute tool; log analysis-based methods identify attack paths and construct attack link graphs by analyzing system logs, security device logs and other data. In addition, with the integration of artificial intelligence and big data technology, machine learning algorithms are widely used in attack behavior pattern recognition and anomaly detection, improving the traceability efficiency. In the industrial internet of things (IIoT) scenario, traceability technology is further combined with physical layer monitoring methods to deal with the unique attack features in industrial control units (ICS).
[0003] Although existing network attack traceability technology shows strong effectiveness in specific scenarios, its adaptability in the industrial internet of things environment still has limitations. First, existing methods rely on static log or traffic feature analysis, making it difficult to respond to dynamic attack behavior in real time. Second, existing methods lack the ability to model the transmission path of attack behavior in the physical-information fusion space. SUMMARY
[0004] In view of the above existing problems, the present application is proposed.
[0005] Therefore, the present application provides a network attack event traceability processing method based on chaotic watermark to solve the problems of insufficient real-time response capability and missing physical layer attack transmission path association.
[0006] To solve the above technical problems, the present application provides the following technical solutions:
[0007] In a first aspect, the present application provides a network attack event traceability processing method based on chaotic watermark, which comprises,
[0008] Collecting real-time data generated by sensors in the industrial internet of things, the real-time data including timestamp, sensor ID, parameter type and parameter value;
[0009] Calculating the uncertainty index of device behavior based on real-time data, and judging potential attack behavior to generate attack judgment flag and abnormal transmission path;
[0010] According to the attack judgment mark and the abnormal conduction path, a chaotic encryption watermark is embedded in a control instruction sent to an executor, to obtain a control instruction stream carrying the watermark;
[0011] The executor responds to the control instruction stream carrying the watermark to complete an operation, while monitoring a deviation value of an execution result from an expected physical behavior to generate an execution deviation value and watermark feedback data;
[0012] Attack source coordinate information is generated based on the execution deviation value and the watermark feedback data, and an attack path atlas is generated to push a traceability report.
[0013] As a preferred scheme of the network attack event traceability processing method based on the chaotic watermark, the specific steps of calculating the uncertainty index of the device behavior based on the real-time data are as follows,
[0014] The real-time data is divided into a plurality of independent data sequence groups;
[0015] The conditional probability is calculated based on the independent data sequence groups using a time window;
[0016] The conditional entropy value is calculated according to the conditional probability to obtain the uncertainty index of the device behavior.
[0017] As a preferred scheme of the network attack event traceability processing method based on the chaotic watermark, the specific steps of judging the potential attack behavior to generate the attack judgment mark and the abnormal conduction path are as follows,
[0018] The abnormal time window is marked according to the uncertainty index of the device behavior;
[0019] The attack judgment mark is generated based on the abnormal time window, and the abnormal conduction path is generated according to the attack judgment mark.
[0020] As a preferred scheme of the network attack event traceability processing method based on the chaotic watermark, the specific steps of embedding the chaotic encryption watermark in the control instruction sent to the executor to obtain the control instruction stream carrying the watermark are as follows,
[0021] The control instruction sent to the executor is received;
[0022] The chaotic watermark initial seed value and the hash value are generated based on the attack judgment mark;
[0023] The chaotic initial value is generated by performing an exclusive or operation on the chaotic watermark initial seed value and the hash value, and the chaotic encryption watermark is generated through a Logistic chaotic mapping iteration formula;
[0024] The perturbable field to be modified in the control instruction is determined according to the abnormal conduction path;
[0025] The chaotic encryption watermark is embedded into the perturbable field to obtain a control instruction stream carrying the watermark.
[0026] As a preferred scheme of the network attack event traceability processing method based on the chaotic watermark, the executor receives the control instruction stream carrying the watermark, obtains an execution result after performing the physical operation, and monitors a deviation value of the execution result from the expected physical behavior, and the specific steps are as follows,
[0027] The executor parses the control instruction stream carrying the watermark, and performs the corresponding physical operation according to the parsing result;
[0028] The physical output value in the process of performing the physical operation is collected in real time to obtain the execution result;
[0029] The control instruction stream carrying the watermark is converted into a physical quantity measurable by a sensor to obtain the expected physical behavior.
[0030] As a preferred scheme of the network attack event traceability processing method based on the chaotic watermark, the execution deviation value and the watermark feedback data are generated, and the specific steps are as follows,
[0031] The absolute value of the difference between the execution result and the expected physical behavior is taken as the deviation value, and the execution deviation value is generated based on the deviation value, the physical output value and the control instruction stream carrying the watermark;
[0032] The watermark feedback data is generated according to the control instruction stream carrying the watermark.
[0033] As a preferred scheme of the network attack event traceability processing method based on the chaotic watermark, the attack source coordinate information is generated based on the execution deviation value and the watermark feedback data, an attack path atlas is generated, a traceability report is pushed, and the specific steps are as follows,
[0034] The tampered bit is located based on the watermark feedback data, and the attack source coordinate information is generated according to the tampered bit and the attack judgment mark;
[0035] The attack path atlas is generated according to the attack source coordinate information, and the traceability report is generated and pushed based on the tampered bit, the attack source coordinate information, the control instruction and the execution deviation value.
[0036] As a preferred scheme of the network attack event traceability processing method based on the chaotic watermark, the real-time data generated by the sensor in the industrial Internet of Things is collected, and the specific steps are as follows,
[0037] A data collection agent is installed on the edge device of the industrial Internet of Things;
[0038] The data collection agent is connected with the sensor of the industrial Internet of Things, and the original data stream is received in real time;
[0039] Converting the raw data stream into structured real-time data.
[0040] In a second aspect, the present application provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and wherein the computer program, when executed by the processor, implements any step of the method for tracing a network attack event based on chaotic watermarking according to the first aspect of the present application.
[0041] In a third aspect, the present application provides a computer readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any step of the method for tracing a network attack event based on chaotic watermarking according to the first aspect of the present application.
[0042] The present application has the following beneficial effects: by dividing the sensor real-time data into independent data sequence groups, dynamic quantitative evaluation of device behavior anomalies is achieved, which can reflect the information disorder degree of device behavior within a specific time window, and can respond to the uncertainty changes of device behavior in real time, triggering an early warning when the attack behavior just causes physical consequences, solving the deficiency of existing methods in real-time aspect; by embedding chaotic encryption watermark in the control instruction, it is difficult for the attacker to bypass the trace detection by simply tampering with the control instruction, ensuring the physical executability of the control instruction, avoiding interference to the industrial process, even if the attacker disguises the IP address or uses a jump node, the tampered bit can still be located through the watermark feedback data, solving the problem of missing association of physical layer attack transmission path. BRIEF DESCRIPTION OF DRAWINGS
[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0044] Fig. 1 Flowchart of the method for tracing a network attack event based on chaotic watermarking.
[0045] Fig. 2 Schematic diagram for generating and embedding chaotic encryption watermark.
[0046] Fig. 3 Schematic diagram for generating execution deviation monitoring and watermark feedback.
[0047] Fig. 4 Schematic diagram for generating a trace report. DETAILED DESCRIPTION
[0048] In order to make the above objectives, characteristics and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0049] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present application. The present application, however, can be practiced in a variety of ways beyond the specific embodiments described herein without departing from the scope of the present application, which is not limited to the specific embodiments described herein. It can be apparent to those skilled in the art that there are more specific embodiments to which the present application can be applied without departing from the scope of the present application.
[0050] Secondly, the "one embodiment" or "embodiment" referred to herein means that the specific features, structures or characteristics can be included in at least one implementation of the present application. "In one embodiment" appearing in different places in the specification does not mean the same embodiment, nor is it an embodiment that is independent of or selected from other embodiments.
[0051] Reference Figs. 1-4 For one embodiment of the present application, the embodiment provides a network attack event tracing processing method based on chaotic watermark, comprising the following steps:
[0052] S1: Collecting real-time data generated by sensors in the industrial Internet of Things, the real-time data including timestamp, sensor ID, parameter type and parameter value.
[0053] The specific steps are as follows,
[0054] S1.1 Installing a data collection agent on the edge device of the industrial Internet of Things, the data collection agent being realized based on an open source framework and used for managing sensor data flow.
[0055] In specific operation, a cross-compilation tool chain corresponding to the edge device of the industrial Internet of Things is used to compile source code of the open source framework, to generate an executable file suitable for the edge device of the industrial Internet of Things; the compiled executable file is transmitted to a designated storage directory of the edge device of the industrial Internet of Things through a secure file transfer protocol;
[0056] A configuration file of the data collection agent is created on the edge device of the industrial Internet of Things, the configuration file setting a port number listened to by the data collection agent and an address list of the industrial Internet of Things sensors; the executable file is added with execution authority in the operating environment of the edge device of the industrial Internet of Things; a start command is executed to run the data collection agent, and the data collection agent loads the configuration file to start listening to the specified port.
[0057] S1.2 Connecting the data collection agent with the industrial Internet of Things sensors through a physical interface, configuring communication parameters and ensuring that the two-way communication is ready.
[0058] S1.3 Subscribe to the sensor data topic through the message queue telemetry transport protocol to receive the raw data stream in real time.
[0059] Further, the message queue telemetry transport agent server address is set in the configuration file of the data collection agent; the message topic section of the configuration file is modified, and the data topic path corresponding to the industrial internet of things sensor is added, each path corresponding to a unique industrial internet of things sensor identifier;
[0060] The data collection agent sends a subscription message to the message queue telemetry transport agent server, and the message queue telemetry transport agent server forwards the corresponding industrial internet of things sensor data to the data collection agent to form a raw data stream.
[0061] S1.4 Extract the timestamp, sensor ID, parameter type and parameter value in the raw data stream and convert them into structured real-time data.
[0062] Specifically, the timestamp, sensor ID, parameter type and parameter value are combined into a comma-separated value format record to form structured real-time data.
[0063] It should be noted that: collecting real-time data generated by sensors in the industrial internet of things is beneficial to ensure the comprehensiveness and real-time nature of data collection, and provides a basis for subsequent analysis; by installing a data collection agent on the edge device of the industrial internet of things to manage sensor data streams, unified monitoring of sensor data in the industrial internet of things is achieved, avoiding data omission or delay problems; subscribing to the sensor data topic using the message queue telemetry transport protocol ensures stable reception of data streams and reduces the risk of communication interruption; extracting the timestamp, sensor ID, parameter type and parameter value and converting them into structured real-time data ensures the standardization of data format, facilitating subsequent processing; step S1 improves the reliability of the entire traceability process, as complete and accurate real-time data is a prerequisite for detecting potential attack behavior; real-time collection of sensor data in the industrial internet of things also supports rapid response to changes in the industrial environment, enhancing the overall resilience of the industrial internet of things system when facing network threats; connecting industrial internet of things sensors through physical interfaces and configuring communication parameters ensures the robustness of bidirectional communication, preventing data from being tampered with or lost during transmission; structured real-time data lays a solid data foundation for uncertainty index calculation, optimizing the accuracy of attack behavior judgment.
[0064] S2: Calculate the uncertainty index of device behavior based on real-time data, and judge potential attack behavior to generate attack judgment flag and abnormal conduction path.
[0065] The specific steps are as follows,
[0066] S2.1 Grouping real-time data by sensor ID and parameter type, forming independent data sequence groups, each group containing parameter values of the same sensor and parameter type.
[0067] S2.2 Setting a fixed time length time window covering real-time data in a continuous timestamp range, the time window sliding forward by a fixed step.
[0068] S2.3 For real-time data in the time window, calculating the conditional probability of parameter values between the current window and the previous window, calculating the conditional entropy value based on the conditional probability, and obtaining the uncertainty index of device behavior.
[0069] Further, extracting parameter values from real-time data in the time window, dividing the value range of parameter values into multiple equal-width intervals, counting the number of parameter values appearing in each interval to form a parameter value distribution histogram;
[0070] Comparing the parameter value distribution histograms of the current time window and the previous time window, taking the ratio of the number of parameter values appearing in each interval to the total number of parameter values appearing in the current time window as the current window interval probability; taking the ratio of the number of parameter values appearing in each interval to the total number of parameter values appearing in the previous time window as the previous window interval probability; taking the ratio of the current window interval probability to the previous window interval probability as the conditional probability value;
[0071] The expression for calculating the conditional entropy value based on the conditional probability is:
[0072] ;
[0073] Wherein, is the conditional entropy value, indicating the uncertainty degree of the parameter value distribution of the current time window relative to the parameter value distribution of the previous time window, is the interval index, is the total number of intervals, is the conditional probability value of the i-th interval of the previous time window, is the conditional probability value of the i-th interval of the current time window. S2.4 Setting an upper threshold based on historical conditional entropy values using the percentile method, for example, sorting the historical conditional entropy values in ascending order, and taking the 95% percentile of the historical conditional entropy values as the upper threshold; if the conditional entropy value exceeds the upper threshold, marking the corresponding time window as an abnormal window.
[0074] S2.4 Setting an upper threshold based on historical conditional entropy values using the percentile method, for example, sorting the historical conditional entropy values in ascending order, and taking the 95% percentile of the historical conditional entropy values as the upper threshold; if the conditional entropy value exceeds the upper threshold, marking the corresponding time window as an abnormal window.
[0075] S2.5 create an attack judgment flag record for each abnormal window, containing the time window start timestamp, sensor ID, parameter type, conditional entropy value, upper threshold value and flag state.
[0076] It should be noted that the time window start timestamp is the first time point of the abnormal window; the flag state is fixed as the string "abnormal".
[0077] S2.6 scan the attack judgment flag record, sort the abnormal sensor IDs, connected device IDs and connected device types corresponding to the adjacent sensors existing in the abnormal window in topological order, and merge them to form an abnormal conduction path.
[0078] It should be noted that: calculating the uncertainty index of the device behavior based on real-time data is beneficial to identifying abnormal patterns in advance and enhancing the detection accuracy of potential attack behavior; grouping real-time data by sensor ID and parameter type to form independent data sequence groups allows for fine-grained analysis of specific industrial Internet of Things devices, avoiding misjudgment caused by data mixing; using time windows for statistical analysis of independent data sequence groups to calculate uncertainty indexes can capture dynamic changes in device behavior, such as quantifying uncertainty through conditional entropy values to discover abnormalities that deviate from normal behavior at an early stage; setting an upper threshold value and marking abnormal time windows improves the objectivity of the judgment and reduces subjective interference by comparing historical conditional entropy values; generating an attack judgment flag record containing the time window start timestamp, sensor ID and parameter type provides a clear attack event evidence chain; scanning the attack judgment flag record to generate an abnormal conduction path reveals the propagation path of the attack in the industrial Internet of Things topology by sorting the abnormal sensor IDs and connected device IDs; step S2 is beneficial to quickly locating potential attack sources, shortening response time, and generating structured output for subsequent watermark embedding; the construction of the abnormal conduction path enhances the visualization of attack behavior, making it easier for security personnel to understand the threat propagation mechanism and improving the overall protection capability of the industrial Internet of Things; the calculation process of the uncertainty index also optimizes resource utilization, avoiding the inefficiency of full data analysis.
[0079] S3: According to the attack judgment flag and the abnormal conduction path, embed a chaotic encryption watermark in the control command sent to the actuator to obtain a control command stream carrying the watermark.
[0080] The specific steps are as follows,
[0081] S3.1 replace the time window start timestamp with a Unix millisecond timestamp format as the chaotic watermark initial seed value; convert the sensor ID into a hash value through the SHA-256 hash algorithm; take the fixed bit bytes of the hash value and perform an exclusive OR operation with the chaotic watermark initial seed value to generate a chaotic initial value; generate a chaotic encryption watermark through the Logistic chaotic mapping iteration formula.
[0082] In a specific operation, a control instruction sent from a controller of an industrial Internet of Things to an actuator is received, a time window start timestamp in an attack judgment flag record is extracted, the time window start timestamp is converted into a millisecond integer value format starting from the Unix epoch time, and the millisecond integer value format is used as a chaotic watermark initial seed value;
[0083] A sensor ID is used as an input, and a fixed-length binary hash value is generated by using an SHA-256 hash algorithm;
[0084] A continuous fixed number of bytes is extracted from a left start position of the hash value to form a binary fragment;
[0085] The chaotic watermark initial seed value and the binary fragment are subjected to a bitwise XOR logical operation: each bit of the chaotic watermark initial seed value and the binary fragment is subjected to a logical judgment, if the values of the two bits at the same position are equal, 0 is output, and if the values of the two bits at the same position are not equal, 1 is output; after all the logical judgments are completed, a chaotic initial value is generated;
[0086] The chaotic initial value is converted into a floating-point number format, the floating-point number is linearly mapped to an interval (0, 1) to obtain a normalized chaotic initial value, and the normalized chaotic initial value is ensured to satisfy an input range requirement of a Logistic chaotic mapping;
[0087] The normalized chaotic initial value is input into a Logistic chaotic mapping standard iteration formula, a first iteration value is output, the first iteration value is input into the Logistic chaotic mapping standard iteration formula, a new iteration value is output, the new iteration value is used as an input of the Logistic chaotic mapping standard iteration formula, and the same iteration calculation is repeatedly executed;
[0088] For each iteration value output in each iteration, a mantissa part of the iteration value is extracted, the mantissa part is converted into a fixed-length binary string, a middle fixed bit segment of the binary string is intercepted to obtain a binary bit segment, and the binary bit segment is prevented from being disturbed by a sign bit; the mantissa part is a decimal part of the iteration value;
[0089] All the binary bit segments are connected in an iteration order, the iteration is stopped when a fixed multiple of a bit number length of the control instruction is reached, and a chaotic encryption watermark is generated.
[0090] S3.2. According to the parameter type, the type of the control instruction to be modified is determined, and a disturbable field in the control instruction is located; the chaotic encryption watermark is divided into independent watermark bits in a bitwise manner, each independent watermark bit corresponds to a disturbable field; the disturbable field of the control instruction is modified according to the independent watermark bit, and a watermark header identifier is added, to form a control instruction stream carrying the watermark.
[0091] Further, the unattacked historical parameter type is integrated with the corresponding control instruction type as an industrial protocol mapping table; the parameter type in the attack judgment flag record is read, and the control instruction type corresponding to the parameter type is obtained by querying the industrial protocol mapping table;
[0092] According to the control instruction type, the perturbable field in the control instruction is located, for example, when the control instruction type is a PID control instruction, the fixed-length mantissa field is located and marked as a perturbable field, when the control instruction type is an analog output instruction, the fixed-length significant digit field is located and marked as a perturbable field, and when the control instruction type is a Boolean control instruction, the state byte reserved bit is located and marked as a perturbable field.
[0093] For the bit value of each perturbable field, if the independent watermark bit value is 1, the bit value of the current perturbable field is flipped, and if the independent watermark bit value is 0, the bit value of the current perturbable field is kept unchanged, to obtain a modified control instruction; an identifier of a fixed number of bits is embedded in the protocol reserved bit of the modified control instruction to obtain a control instruction stream carrying a watermark, and the identifier is a binary sequence.
[0094] It should be further noted that: embedding a chaotic encryption watermark in the control instruction according to the attack judgment flag and the abnormal conduction path is beneficial to enhancing the tamper resistance and traceability of the instruction stream; generating a chaotic initial value based on the time window start timestamp in the attack judgment flag and the sensor ID ensures the uniqueness and unpredictability of the watermark, preventing attackers from forging or copying; iteratively generating a chaotic encryption watermark utilizes the dynamic characteristics of chaotic mapping, making the watermark highly random and improving the resistance to malicious interference; determining the perturbable field to be modified in the control instruction according to the parameter type in the abnormal conduction path, and selectively embedding the watermark in the field, for example, in the mantissa field of a PID control instruction or the significant digit field of an analog output instruction, realizes seamless integration of the watermark and the instruction content; embedding the chaotic encryption watermark in the perturbable field to obtain a control instruction stream carrying a watermark provides an additional security layer, as any tampering attempt will cause the watermark characteristics to change, facilitating subsequent verification; step S3 is beneficial to maintaining instruction integrity and ensuring that the instructions received by the executor come from a trusted source; embedding the chaotic encryption watermark also supports real-time monitoring, as it forms a closed loop with the watermark feedback data, laying a foundation for attack source coordinate information generation; the control instruction stream carrying the watermark simplifies communication management in the industrial Internet of Things, reducing the risk of physical operation deviation caused by tampered instructions; the addition of the watermark header identifier improves the identification efficiency of the instructions and optimizes the efficiency of the entire traceability process.
[0095] S4: The executor responds to the control instruction stream carrying the watermark to complete the operation, while monitoring the deviation value between the execution result and the expected physical behavior, to generate an execution deviation value and watermark feedback data.
[0096] The specific steps are as follows,
[0097] S4.1 The executor sequentially receives the control instruction stream carrying the watermark, parses the instruction content of the control instruction stream carrying the watermark, and executes the physical operation according to the instruction content.
[0098] Specifically, the executor receives the control instruction stream carrying the watermark in real time through the industrial Ethernet interface, stores the data packet into the ring buffer, reorganizes the continuous instruction sequence according to the protocol frame sequence number; extracts the encrypted field from the continuous instruction sequence, decrypts the encrypted field using the key, and obtains the instruction content;
[0099] The instruction content is used to drive the physical device to execute the physical operation, for example, the speed setting value in the instruction content is input into the servo driver, the rotor position is adjusted using closed-loop control, the opening percentage in the instruction content is sent to the positioner, the pneumatic actuator pushes the valve core to the opening percentage position, and the Boolean state in the instruction content is written into the relay coil to close / open the main circuit contact.
[0100] S4.2 Real-time acquisition of physical output values in the process of executing the physical operation to obtain the execution result; extracting the expected value field from the control instruction and converting it into a sensor measurable physical quantity to obtain the expected physical behavior; the absolute value of the difference between the execution result and the expected physical behavior is taken as the deviation value.
[0101] It should be noted that in the process of executing the physical operation, the physical output value is collected in real time, for example, in the motor operation, the actual speed of the rotor is captured using a laser speedometer, in the valve operation, the real-time flow of the pipeline is recorded using a pressure transmitter, and in the switch operation, the circuit working current is monitored using a current transformer. Each acquisition generates a physical output value record with a millisecond-level timestamp;
[0102] The expected value field is extracted from the control instruction stream carrying the watermark, for example, for the PID control instruction, the speed setting value in the set value register is read, the range coefficient and the opening percentage are read from the analog output instruction, for the Boolean instruction, the binary bit value of the state register is read;
[0103] The expected value field is converted into a sensor measurable physical quantity, for example, the speed setting value is taken as the expected speed value, the product of the range coefficient and the opening percentage is taken as the expected flow value, if the binary bit value is 1, the rated working current is taken as the expected current value, and if the binary bit value is 0, the expected current value is set to 0.
[0104] S4.3 Extract the identifier and the perturbable field from the control instruction stream carrying the watermark, verify whether the identifier is consistent with the identifier embedded in S3.2, if not, mark it as an abnormal identifier, stop the physical operation of the current control instruction execution, and lock the executor operation permission;
[0105] record the binary sequence of the abnormal identifier, the timestamp of the time when the physical operation of the current control instruction execution is suspended, the binary sequence of the abnormal identifier and the control instruction type as an attack feature label;
[0106] re-generate the identifier, send the watermark verification instruction to the executor, and re-verify the identifier.
[0107] It should be noted that the identifier is identical to the identifier embedded in S3.2 only when all bit values are identical, otherwise, it is determined that the identifier is identical to the identifier embedded in S3.2.
[0108] S4.4 If the identifier is identical to the identifier embedded in S3.2, record the deviation value, the timestamp of the time when the physical output value is collected, and the control instruction as the execution deviation value, and record the identifier and the perturbable field as the watermark feedback data.
[0109] It should be noted that: the completion of the operation of the executor in response to the control instruction stream carrying the watermark is beneficial to the accuracy of real-time verification of physical behavior, and feedback data is generated to strengthen the traceability; parsing the control instruction stream carrying the watermark and executing the corresponding physical operation according to the parsing result ensures that the instruction is correctly interpreted and executed, for example, driving the servo driver to adjust the rotor position or controlling the pneumatic actuator to push the valve core, which improves the operation reliability. Real-time collection of the actual physical output value of the physical operation obtains the execution result, which provides an objective physical state record for comparison with the expected value; the expected value field is extracted from the control instruction stream and converted into a physical quantity measurable by a sensor to obtain the expected physical behavior, which ensures the accuracy of the comparison benchmark and avoids misjudgment; the absolute value of the difference between the execution result and the expected physical behavior is calculated to generate the execution deviation value, which quantifies the operation deviation and helps to identify potential attack effects; the watermark identifier and the perturbable field are extracted from the control instruction stream to generate the watermark feedback data, which provides watermark state information and prepares input for subsequent effectiveness verification; step S4 is beneficial to quickly detecting abnormal operation because the execution deviation value and the watermark feedback data directly reflect the attack consequences; the generation of the watermark feedback data also promotes closed-loop control and supports real-time verification of chaotic encryption watermark; the deviation monitoring during the operation of the executor optimizes the response speed, and the generation of the execution deviation value and the watermark feedback data is beneficial to reducing false positives and improving credibility through matching of physical behavior and actual output; step S4 strengthens the resilience of industrial Internet of Things and ensures that the physical operation is consistent with the control instruction.
[0110] S5: Based on the execution deviation value and the watermark feedback data, generate attack source coordinate information and generate an attack path map, and push a traceability report.
[0111] The specific steps are as follows,
[0112] S5.1 input the normalized chaotic initial value in step S3.1 into the Logistic chaotic mapping standard iteration formula to iteratively generate a chaotic sequence; extract the perturbable field in the control instruction, calculate the Hamming distance between the perturbable field and the corresponding bit value in the chaotic sequence, if the Hamming distance does not exceed a fixed proportion of the total number of bits, mark it as a valid watermark, if the Hamming distance exceeds a fixed proportion of the total number of bits, mark it as a tampered bit.
[0113] Further, calculate the Hamming distance between the perturbable field and the corresponding bit value in the chaotic sequence: compare the perturbable field and the corresponding bit value in the chaotic sequence bit by bit, and take the index position where the same index bit value is not equal as a difference bit. The Hamming distance is the number of difference bits.
[0114] S5.2 associate the timestamp corresponding to the identifier with the start timestamp of the time window in S2.5; based on the tampered bit, obtain the attacked device number by locating the controlled device register address, and take the position corresponding to the attacked device number as the attack source coordinate information.
[0115] It should be noted that if the difference between the timestamp corresponding to the identifier and the start timestamp of the time window does not exceed a fixed time, it is determined to be the same event time point.
[0116] S5.3 construct the connection relationship between devices into a device topology graph; represent the node corresponding to the attacked device number in the device topology graph with a red node; from the abnormal conduction path in S2.6, extract the devices connected with the attack device number, and represent the corresponding nodes with yellow nodes.
[0117] In specific operation, the connection relationship and connection direction between devices are collected, each device is taken as a node, and the nodes are connected according to the connection relationship and connection direction between devices. The nodes are green by default.
[0118] S5.4 read the attack source coordinates from the attack source coordinate information, take the ratio of the number of tampered bits to the number of perturbable field bits as the proportion of tampered bits, define the control instruction type and the proportion of tampered bits as the attack type, take the maximum deviation value recorded in the execution deviation value as the maximum physical deviation; combine the attack source coordinates, the attack type, the maximum physical deviation and the device topology graph into a traceability report.
[0119] It should be noted that: based on the execution deviation value and the watermark feedback data to generate the attack source coordinate information is beneficial to accurately locate the attack source and optimize the response mechanism; verifying the effectiveness of the chaotic encryption watermark in the watermark feedback data and locating the tampered bit confirms the watermark integrity, which facilitates the differentiation between normal operation and attack interference; generating the attack source coordinate information according to the timestamp association relationship between the tampered bit and the attack judgment flag; based on the attack source coordinate information and the device topology graph, marking the attacked device node and generating the attack path graph, visualizing the attack diffusion path, for example, using red nodes to represent the attacked device number nodes and yellow nodes to represent the connected device nodes, enhancing the understandability of the threat; merging the attack source coordinate information, the attack type, the maximum physical deviation and the attack path graph into the traceability report, integrating the key information, and facilitating comprehensive analysis of the attack event; pushing the traceability report to the security monitoring terminal, realizing the instant delivery of information, and supporting rapid decision-making; step S5 is beneficial to shorten the traceability time, because the attack source coordinate information and the attack path graph are directly derived from the execution deviation value and the watermark feedback data, reducing the need for manual intervention; the generation of the attack path graph also optimizes the security audit of the industrial Internet of Things, because it is based on the device topology graph, ensuring the accuracy of the path; pushing the traceability report is beneficial to collaborative response and improves the overall security level; the process of generating the attack source coordinate information strengthens the traceability of attack behavior and reduces the risk of similar events in the future; merging the traceability report provides a unified output, facilitating the storage and analysis of historical attack events.
[0120] The embodiment also provides a computer device suitable for the network attack event traceability processing method based on chaotic watermark, which comprises a memory and a processor.
[0121] The computer device can be a terminal, which comprises a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device comprises a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be realized through WIFI, operator network, NFC (near field communication) or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device. In addition, an external keyboard, touchpad or mouse can also be used.
[0122] The embodiment also provides a storage medium on which a computer program is stored, the program being executed by a processor to implement a method for tracing a network attack event based on chaotic watermarking proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk.
[0123] To sum up, the present application achieves dynamic quantitative evaluation of equipment behavior anomaly by dividing sensor real-time data into independent data sequence groups, can reflect the information confusion degree of equipment behavior in a specific time window, can respond to the uncertainty change of equipment behavior in real time, triggers early warning when the attack behavior just causes physical consequences, and solves the deficiency of real-time performance of the prior art; by embedding chaotic encryption watermark in the control instruction, it is difficult for the attacker to bypass the traceability detection by simply tampering with the control instruction, ensures the physical executability of the control instruction, avoids interference to the industrial process, even if the attacker disguises the IP address or uses a jump node, the tampered bit can still be located through the watermark feedback data, and solves the problem of missing association of the physical layer attack transmission path.
[0124] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application but not limit the present application, although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the present application, and all should be covered in the scope of the claims of the present application.
Claims
1. A method for tracing and processing network attack events based on chaotic watermarking, characterized in that: include, Collect real-time data generated by sensors in the Industrial Internet of Things (IIoT), including timestamps, sensor IDs, parameter types, and parameter values. Based on real-time data, the uncertainty index of device behavior is calculated, potential attack behaviors are identified, and attack judgment flags and abnormal propagation paths are generated. Based on the attack detection flag and the abnormal propagation path, a chaotic encrypted watermark is embedded in the control command sent to the executor to obtain a control command stream carrying the watermark. The specific steps for embedding a chaotic encrypted watermark in the control commands sent to the actuator to obtain a control command stream carrying the watermark are as follows. Receive control commands sent to the actuator; Generate the initial seed value and hash value of the chaotic watermark based on the attack detection flag; The initial seed value of the chaotic watermark is XORed with the hash value to generate the initial chaotic value, and the chaotic encrypted watermark is generated by the Logistic chaotic mapping iterative formula. Determine the perturbable fields to be modified in the control command based on the abnormal transmission path; Embed the chaotic encrypted watermark into a perturbable field to obtain a control command stream carrying the watermark; The actuator receives a control command stream carrying a watermark, performs physical operations and obtains the execution result, while monitoring the deviation between the execution result and the expected physical behavior, and generating execution deviation value and watermark feedback data. Based on the execution deviation value and watermark feedback data, attack source coordinate information is generated, and an attack path map is generated, and a source tracing report is pushed out.
2. The network attack event tracing and processing method based on chaotic watermarking as described in claim 1, characterized in that: The uncertainty index for calculating device behavior based on real-time data is determined through the following specific steps. Divide real-time data into multiple independent data sequence groups; Conditional probabilities are calculated using time windows based on independent data sequence groups. The conditional entropy value is calculated based on the conditional probability to obtain the uncertainty index of the equipment behavior.
3. The network attack event tracing and processing method based on chaotic watermarking as described in claim 1, characterized in that: The specific steps for determining potential attack behaviors and generating attack detection flags and abnormal propagation paths are as follows. Mark abnormal time windows based on uncertainty indicators of equipment behavior; An attack determination flag is generated based on the abnormal time window, and an abnormal propagation path is generated based on the attack determination flag.
4. The network attack event tracing and processing method based on chaotic watermarking as described in claim 1, characterized in that: The actuator receives a control command stream carrying a watermark, performs physical operations, obtains the execution result, and simultaneously monitors the deviation between the execution result and the expected physical behavior. The specific steps are as follows. The actuator parses the control command stream carrying the watermark and performs the corresponding physical operation based on the parsing result; Real-time acquisition of physical output values during the execution of physical operations yields the execution results; The control command stream carrying the watermark is converted into a sensor-measurable physical quantity to obtain the expected physical behavior.
5. The network attack event tracing and processing method based on chaotic watermarking as described in claim 4, characterized in that: The specific steps for generating the execution deviation value and watermark feedback data are as follows: The absolute value of the difference between the execution result and the expected physical behavior is used as the deviation value. An execution deviation value is generated based on the deviation value, the physical output value, and the control instruction stream carrying the watermark. Watermark feedback data is generated based on the control command stream carrying the watermark.
6. The network attack event tracing and processing method based on chaotic watermarking as described in claim 1, characterized in that: The steps for generating attack source coordinates based on execution deviation values and watermark feedback data, generating an attack path map, and pushing a source tracing report are as follows: Based on the watermark feedback data, the tampered position is located, and the coordinate information of the attack source is generated according to the tampered position and the attack judgment flag. An attack path map is generated based on the coordinates of the attack source, and a source tracing report is generated and pushed based on the tampered bits, the coordinates of the attack source, the control commands, and the execution deviation values.
7. The network attack event tracing and processing method based on chaotic watermarking as described in claim 1, characterized in that: The specific steps for collecting real-time data generated by sensors in the Industrial Internet of Things (IIoT) are as follows. Install data acquisition agents on edge devices of the Industrial Internet of Things; Connect the data acquisition agent to industrial IoT sensors and receive raw data streams in real time; Transform raw data streams into structured real-time data.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the network attack event tracing and processing method based on chaotic watermarking as described in any one of claims 1 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the network attack event tracing and processing method based on chaotic watermarking as described in any one of claims 1 to 7.
Citation Information
Patent Citations
System for providing a real-time attacking connection traceback using a packet watermark insertion technique and method therefor
US20040049695A1